Written by a human

FCA Conduct Rules and COCON Explained

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
14 mins read 16 September 2026

In brief:

  • The FCA Conduct Rules are minimum standards of individual behavior for people working in regulated financial services. They are contained in the FCA Handbook’s Code of Conduct sourcebook, known as COCON.
QuestionPractical answer
Who is generally covered?Most employees at firms subject to the Senior Managers and Certification Regime, with limited exclusions for specified ancillary staff
How many Individual Conduct Rules are there?Six, although Rule 6 applies only where the individual’s activities fall within the Consumer Duty
What applies to Senior Managers?The Individual Conduct Rules plus four additional Senior Manager Conduct Rules
What must firms do?Identify in-scope staff, notify them of the rules, provide suitable training, investigate suspected breaches, preserve evidence, and report qualifying outcomes
Does every mistake amount to a breach?The assessment depends on the rule, the individual’s responsibilities, knowledge, seniority, conduct, and the surrounding circumstances
How are breaches reported?Reporting depends on the individual’s status, seriousness, and whether disciplinary action occurred
What changes on September 1, 2026?Serious work-related bullying, harassment, and violence will be brought expressly within COCON for relevant staff at non-bank firms

What are the FCA Conduct Rules?

The FCA Conduct Rules establish minimum standards of personal conduct for individuals working in regulated financial services. They are intended to improve behavior throughout firms, encourage employees to take responsibility for their actions, and make clear that regulatory accountability does not rest with the legal entity alone.

The rules form one of the three parts of the Senior Managers and Certification Regime, alongside the Senior Managers Regime and the Certification Regime. The first two focus on responsibility and suitability for particular roles; the Conduct Rules establish behavioral standards across a wider employee population.

See The Senior Managers and Certification Regime Explained for the complete accountability framework.

The Conduct Rules apply directly to individuals. An employee or Senior Manager can breach a rule through an act or omission, even where the firm also has responsibility for wider weaknesses in governance, supervision, systems, or controls.

They are deliberately principles-based. A firm should not decide whether a breach occurred simply by matching an event to a short label. It must consider the rule, the person’s role and authority, the information available at the time, the action reasonably expected, and the seriousness and consequences of the conduct.

What is COCON?

COCON is the FCA Handbook’s Code of Conduct sourcebook. It sets out the scope of the Conduct Rules, the six Individual Conduct Rules, the four additional Senior Manager Conduct Rules, training expectations, and guidance for assessing conduct.

The operative rules appear in COCON 2, with further guidance in COCON 3 and COCON 4.

COCON is not merely an internal code of ethics. It is part of the FCA Handbook and can affect disciplinary action, certification, fitness and propriety, regulatory references, notifications, and enforcement.

A firm may adopt internal conduct standards that go beyond COCON, but it should distinguish clearly between a breach of company policy and a regulatory Conduct Rule breach. The same facts can support both conclusions, but the tests and consequences are not automatically identical.

Who do the Conduct Rules apply to?

The Conduct Rules generally apply to most staff at firms within SM&CR. This includes Senior Managers, Certification Staff, non-Senior Manager directors, and other employees whose work is connected with the firm’s regulated or financial-services activities.

The FCA’s scope can also capture contractors, temporary workers, secondees, and volunteers, depending on the arrangement.

Specified ancillary roles are generally excluded. Examples can include receptionists, security staff, cleaners, catering staff, and other roles that are not specific to financial services. Scope still depends on the firm and the work actually performed, so a job title should not be used as the only test.

Senior Managers are subject to both the Individual Conduct Rules and the additional Senior Manager Conduct Rules. Other conduct-rules staff are generally subject only to the Individual Conduct Rules relevant to their work.

Rule 6, which requires individuals to act to deliver good outcomes for retail customers, applies in connection with activities within the scope of the Consumer Duty. It does not apply to every employee or every activity.

Firms should maintain an accurate in-scope population and revisit it when employees change role, responsibility, legal entity, employment status, or business activity.

What are the six Individual Conduct Rules?

The current rules are set out in COCON 2.1.

RuleRequired standardExamples of potential concern
Rule 1Act with integrityDishonesty, misleading statements, falsified records, concealment, or deliberate circumvention of controls
Rule 2Act with due skill, care and diligenceCareless execution, inadequate supervision, failure to understand responsibilities, or failure to respond to known risk
Rule 3Be open and cooperative with the FCA, PRA, and other regulatorsObstruction, incomplete or misleading information, or failure to escalate matters requiring regulatory consideration
Rule 4Pay due regard to customer interests and treat them fairlyUnfair pressure, unsuitable recommendations, omitted information, or disregard of foreseeable customer harm
Rule 5Observe proper standards of market conductInsider dealing, manipulation, improper disclosure, misleading market behavior, or disregard of recognized market standards
Rule 6Act to deliver good outcomes for retail customersConduct inconsistent with the firm’s Consumer Duty obligations within the individual’s role

Integrity is broader than compliance with criminal law. Due skill, care, and diligence is role-specific and depends on experience, seniority, responsibilities, and risk. Managers who are not Senior Managers can breach Rule 2 through inadequate supervision or failure to address recognizable problems.

Rule 3 requires openness and cooperation, supported by escalation arrangements that bring relevant information to the appropriate internal and regulatory channels.

Rules 4 and 6 overlap but are not identical. Rule 4 is the established obligation to consider customer interests and treat customers fairly. Rule 6 reflects the Consumer Duty’s outcomes-focused standard for retail business.

Rule 5 requires individuals to observe proper market standards. The firm may need to consider market-abuse law, FCA rules, recognized market practices, venue rules, and industry codes when assessing the person’s conduct.

What are the Senior Manager Conduct Rules?

Senior Managers must comply with four additional rules reflecting their authority, oversight responsibilities, and ability to influence the firm.

Senior Manager ruleRequired standard
SC1Take reasonable steps to ensure the business for which the Senior Manager is responsible is controlled effectively
SC2Take reasonable steps to ensure that business complies with relevant regulatory requirements and standards
SC3Delegate responsibilities to an appropriate person and oversee the delegated responsibility effectively
SC4Disclose appropriately information of which the FCA or PRA would reasonably expect notice

The formal wording appears in COCON 2.2, while COCON 4.2 provides detailed guidance on reasonable steps and the application of each rule.

Reasonable steps do not require a Senior Manager to prevent every failure. The assessment considers allocated responsibilities, business complexity, available information, resources, controls, and the response to identified weaknesses.

Delegation is often necessary, but it does not remove accountability. The manager should select an appropriate delegate, make responsibilities clear, maintain proportionate oversight, challenge performance, and intervene where controls or outcomes are inadequate.

Evidence can include the Statement of Responsibilities, committee records, management information, delegation arrangements, decisions, escalations, challenges, resourcing requests, and remediation activity.

How does the FCA assess a possible breach?

A mistake, policy failure, or poor outcome does not automatically establish a Conduct Rule breach. The firm should assess the individual’s personal behavior against the rule that applied.

Relevant considerations include what the individual knew, what responsibilities they held, what options were reasonably available, whether they sought advice or escalated concerns, and whether the behavior was deliberate, reckless, negligent, repeated, or an isolated error.

The firm should also consider seniority, competence, training, the adequacy of relevant systems and supervision, actual or potential harm, and how the person responded after the issue was identified.

COCON 4.1 provides non-exhaustive examples of conduct that may breach the Individual Conduct Rules. Those examples support judgment; they should not be treated as an exhaustive checklist.

Employment misconduct, performance concerns, policy breaches, market abuse, fitness-and-propriety issues, and Conduct Rule breaches may arise from the same event, but the firm should record each conclusion separately.

What training must firms provide?

COCON 2.3 requires an SMCR firm to notify people of the Conduct Rules applying to them and take reasonable steps to ensure they understand how those rules relate to their work.

Training should therefore be role-specific. Reproducing the wording of the rules without applying it to actual responsibilities is unlikely to give employees the understanding the framework requires.

A useful program applies the rules to realistic scenarios, escalation expectations, and the consequences of a substantiated breach.

Training should reflect the firm’s products, customers, markets, communications channels, and conduct risks. A trader, retail adviser, surveillance analyst, line manager, and Senior Manager may need different examples even where several of the same rules apply.

Firms should retain evidence of training content, attendance, knowledge checks, refresher activity, role mapping, and updates made after regulatory or organizational change.

What should happen when a possible breach is identified?

A consistent investigation process should preserve fairness while ensuring the regulatory question is not lost inside a wider HR or disciplinary case.

  1. Preserve relevant evidence. Secure communications, calls, trading or customer records, case files, policies, approvals, and management information.
  2. Establish the person’s role. Identify their responsibilities, applicable rules, knowledge, authority, and realistic options.
  3. Separate the tests. Consider employment policy, COCON, fitness and propriety, customer or market harm, and separate notification duties independently.
  4. Obtain the individual’s response. Assess their explanation, evidence, intent, decisions, and any escalation or remediation.
  5. Reach the Conduct Rule conclusion. Identify the rule, facts, expected standard, and why the conduct did or did not fall below it.
  6. Determine consequences and reporting. Consider disciplinary action, certification, remuneration, references, remediation, and FCA notification.
  7. Record the rationale. Preserve enough detail to demonstrate a fair, evidence-based, and consistently governed decision.

Communications can be central because they may establish what a person knew, what they instructed, whether they challenged or escalated, and how they described their purpose at the time.

When must breaches be reported to the FCA?

The FCA’s Conduct Rules guidance distinguishes reporting by individual status and disciplinary outcome.

For an SMF manager, a firm generally must notify the FCA within seven business days after concluding disciplinary action for a Conduct Rule breach. The firm normally uses Form D, or Form C where the individual is leaving the Senior Management Function.

For conduct-rules staff who are not SMF managers, qualifying breaches that result in disciplinary action are generally reported annually through REP008. The FCA defines relevant disciplinary action as a formal written warning, suspension, dismissal, or reduction or recovery of remuneration.

Since August 2025, solo-regulated firms with nothing to report generally do not need to submit a nil REP008 return. The FCA’s REP008 guidance explains the reporting periods, deadlines, and people who should be included.

The 2026 SM&CR reforms also require firms to examine whether immediate notification is necessary for certain senior conduct-rules staff who are not SMF managers. Under SUP 15.11, immediate notification can be relevant where a Senior Manager Conduct Rule breach results in disciplinary action or where a COCON breach is significant under the separate SUP 15 notification framework.

Firms should therefore not assume that annual REP008 reporting is the only possible route for a non-SMF employee. The same conduct may also trigger notification under SUP 15, market-abuse reporting, whistleblowing, criminal reporting, or another requirement.

An appeal does not normally postpone Conduct Rule reporting. The notification should identify the appeal, with the outcome updated through the applicable process.

How do Conduct Rules connect to fitness and propriety?

The Conduct Rules and the Fit and Proper test answer different questions.

COCON assesses whether particular behavior breached an applicable conduct standard. FIT assesses whether the person remains suitable to perform a specific regulated role, considering honesty, integrity, reputation, competence, capability, and financial soundness.

A serious or repeated Conduct Rule breach may affect annual certification, continued Senior Manager approval, role suitability, remuneration, or a regulatory reference. It does not automatically make the person unfit.

Conduct can also be relevant to fitness and propriety even where it falls outside COCON. Firms should document the Conduct Rule assessment and the fitness-and-propriety conclusion separately.

See FCA Fit and Proper Test Explained for the complete FIT framework.

How do the Conduct Rules apply to non-financial misconduct?

On September 1, 2026, new FCA rules and guidance will extend the Conduct Rules for non-bank firms so that serious work-related bullying, harassment, or violence toward colleagues can fall expressly within scope.

The new rule applies where there is a sufficient work-related connection. It can cover conduct on firm premises, remote-working interactions, firm events, offsite training, and other work-related contexts. Purely private-life conduct remains outside COCON, although it may separately be relevant to fitness and propriety.

Only serious misconduct is intended to fall within scope. Firms must consider purpose, effect, repetition, seniority, context, and other relevant circumstances. The conduct does not need to relate to a protected characteristic, although that can increase seriousness.

Managers may breach Rule 2 where they fail to take reasonable steps to prevent misconduct or respond appropriately to complaints within their knowledge and authority.

The change is not retrospective and applies to relevant conduct occurring on or after September 1, 2026. The FCA’s non-financial misconduct guidance states that firms do not need to monitor employees’ private lives or private social-media accounts, investigate trivial or implausible private allegations, or act contrary to privacy or employment law.

See:

How should firms govern Conduct Rules compliance?

An effective framework begins with an accurate in-scope population and documented mapping of the rules to each role.

HR, Compliance, Legal, business management, and regulatory reporting teams should agree how potential cases are escalated and who owns the regulatory conclusion. A disciplinary decision should not automatically become a COCON finding, and a regulatory concern should not be overlooked because an HR process reached a different outcome.

Policies covering conduct, customer treatment, market behavior, communications, whistleblowing, investigations, remuneration, certification, and references should work together.

Management information should show case age, outcomes, reporting status, recurring themes, and overdue remediation. Quality assurance should test whether the evidence and reasoning support the conclusion.

Common weaknesses include generic training, inaccurate staff populations, poor communication between HR and Compliance, inconsistent breach thresholds, delayed reporting, weak evidence preservation, and failure to connect conduct findings with certification and references.

Frequently asked questions

What does COCON stand for?

COCON is the FCA Handbook’s Code of Conduct sourcebook.

How many Individual Conduct Rules are there?

There are six. Rule 6 applies to activities within the scope of the Consumer Duty.

How many additional rules apply to Senior Managers?

Four additional rules cover effective control, regulatory compliance, delegation, and disclosure to regulators.

Do the rules apply to every employee?

They apply broadly across SMCR firms, but specified ancillary roles are excluded and scope depends on the work performed.

Does every mistake breach a Conduct Rule?

The firm must assess the person’s responsibilities, knowledge, actions, circumstances, and the relevant standard.

What counts as disciplinary action for reporting?

A formal written warning, suspension, dismissal, or reduction or recovery of remuneration.

Are COCON and the Fit and Proper test the same?

COCON assesses behavior; FIT assesses continuing suitability for a role.

Can non-financial misconduct breach the Conduct Rules?

Serious work-related misconduct can fall within COCON, with expanded rules for non-bank firms taking effect on September 1, 2026.

How Global Relay helps

Conduct Rule investigations often depend on reliable evidence of what employees and managers communicated, knew, escalated, and decided.

Global Relay captures and preserves business communications across email, mobile, voice, financial messaging, collaboration platforms, and other channels.

Global Relay Communications Surveillance can help firms identify potential market-conduct, customer-treatment, off-channel, and non-financial misconduct risks for proportionate human review. Global Relay Archive preserves the underlying communications and audit history that may support investigation, escalation, and regulatory response.

Learn more about Global Relay Communications Surveillance and Global Relay Archive.

Related reading:

Global Relay Compliant business communications archiving, messaging, supervision, and eDiscovery
14 mins read 16 September 2026